← back
CVE-2024-42448criticalobserved exploitationCWE-94

CVE-2024-42448

75Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.9epss 20%
from disclosure to weapon0 days
Published on NVDDec 11
1st PoCDec 5
VulnCheck+43d
exploitation probability
20%top 3% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short

A flaw in VSPC server allows an authorized management agent to execute arbitrary code remotely on the server machine. This is critical because it gives attackers complete control over the VSPC system if they compromise the management agent.

Technical detail

CWE-94 (Improper Control of Generation of Code) enables Remote Code Execution when an authenticated management agent communicates with the VSPC server. The vulnerability requires prior authorization of the management agent on the server; exploitation results in arbitrary code execution with server-level privileges.

Summary generated and translated by AI from the official description.
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.